SigmaHQ/rules/windows/sysmon
2021-04-12 16:26:15 -04:00
..
sysmon_accessing_winapi_in_powershell_credentials_dumping.yml Update sysmon_accessing_winapi_in_powershell_credentials_dumping.yml 2020-10-13 22:32:55 +02:00
sysmon_ads_executable.yml review windows/sysmon 2020-08-29 02:03:28 +02:00
sysmon_alternate_powershell_hosts_pipe.yml review windows/sysmon 2020-08-29 02:03:28 +02:00
sysmon_apt_turla_namedpipes.yml fixed various spelling errors all over rules and source code 2021-02-24 14:43:13 +00:00
sysmon_cactustorch.yml Remove additional backlash 2020-11-20 02:04:28 -03:00
sysmon_cobaltstrike_process_injection.yml review windows/sysmon 2020-08-29 02:03:28 +02:00
sysmon_createremotethread_loadlibrary.yml review windows/sysmon 2020-08-29 02:03:28 +02:00
sysmon_cred_dump_tools_named_pipes.yml review windows/sysmon 2020-08-29 02:03:28 +02:00
sysmon_dcom_iertutil_dll_hijack.yml update - GitHub Action / Test Sigma 2020-10-12 21:58:02 -04:00
sysmon_dns_hybridconnectionmgr_servicebus.yml HybridConnectionMgr Service Activity 2021-04-12 16:26:15 -04:00
sysmon_mal_namedpipes.yml fixed various spelling errors all over rules and source code 2021-02-24 14:43:13 +00:00
sysmon_new_application_appcompat.yml Fixes&improvements 2021-04-08 01:06:40 +02:00
sysmon_password_dumper_lsass.yml fix: adding only as a known false positive as it cannot be filtered out in a generic and public way 2021-04-01 14:37:15 +02:00
sysmon_possible_dns_rebinding.yml review windows/sysmon 2020-08-29 02:03:28 +02:00
sysmon_powershell_execution_pipe.yml Fixes&improvements 2021-04-08 01:06:40 +02:00
sysmon_psexec_pipes_artifacts.yml Update sysmon_psexec_pipes_artifacts.yml 2020-10-07 14:43:25 +03:00
sysmon_raw_disk_access_using_illegitimate_tools.yml Rule fixes 2020-02-20 23:00:16 +01:00
sysmon_regedit_export_to_ads.yml Fixed field typo 2020-10-15 15:27:11 +02:00
sysmon_removal_com_hijacking_registry_key.yml update - GitHub Action / Test Sigma 2020-10-12 21:58:02 -04:00
sysmon_startup_folder_file_write.yml Fixes&improvements 2021-04-08 01:06:40 +02:00
sysmon_susp_pfx_file_creation.yml 16 rules from DH APT29 day 1 - contributing soon 2020-10-12 18:13:13 -04:00
sysmon_susp_powershell_rundll32.yml Merge branch 'oscd' 2021-03-02 22:58:41 +03:00
sysmon_susp_system_drawing_load.yml Fixes&improvements 2021-04-08 01:06:40 +02:00
sysmon_suspicious_remote_thread.yml review windows/sysmon 2020-08-29 02:03:28 +02:00
sysmon_sysinternals_sdelete_file_deletion.yml 16 rules from DH APT29 day 1 - contributing soon 2020-10-12 18:13:13 -04:00
sysmon_wmi_event_subscription.yml review windows/sysmon 2020-08-29 02:03:28 +02:00
sysmon_wmi_susp_scripting.yml Update detection Logic 2020-11-20 02:10:27 -03:00
sysmon_wmiprvse_wbemcomn_dll_hijack.yml Fixes&improvements 2021-04-08 01:06:40 +02:00